Malware

Win32/Kryptik.GAEW removal guide

Malware Removal

The Win32/Kryptik.GAEW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GAEW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GAEW?


File Info:

crc32: E369E3A3
md5: b30494e5742b8e9d6b2f3f60e69af01f
name: B30494E5742B8E9D6B2F3F60E69AF01F.mlw
sha1: a59bf4995b269682c87f8aef49e451ce544ee70f
sha256: 398e3834cee3b2f3e5c5e07a6921820ec69c1d43ce7dc34e09c7b1df996f8109
sha512: f8e9f67fbc14c956b097011cdc4b6087ab124a341782302d858bcb865a0ce4c8a3478e1a41b08b7afca62918c7d7817e308a8593b96481b800ab9a0d45704230
ssdeep: 12288:tk/eRU0t6UyxLGOrR5K0GTO0SufleiUxuDlX+xcvVT/w9IKr7:tSeRN6npLMCNHiU8DIP7v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9Northglide 1999 - 2014
InternalName: Inversion Embodies
FileVersion: 3.6.2.9
CompanyName: Northglide
PrivateBuild: 3.6.2.9
LegalTrademarks: Copyright xa9Northglide 1999 - 2014
Comments: Ntuser Shared Right Accessing 0xff Ppnent
ProductName: Inversion Embodies
ProductVersion: 3.6.2.9
FileDescription: Ntuser Shared Right Accessing 0xff Ppnent
OriginalFilename: Inversion Embodies.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GAEW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056e96f1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.15589
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Shade.27
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Yakes.0109dea2
K7GWTrojan ( 0056e96f1 )
Cybereasonmalicious.5742b8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GAEW
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Yakes.vpjc
BitDefenderGen:Variant.Ransom.Shade.27
NANO-AntivirusTrojan.Win32.Yakes.exxama
MicroWorld-eScanGen:Variant.Ransom.Shade.27
TencentWin32.Trojan.Yakes.Pbom
Ad-AwareGen:Variant.Ransom.Shade.27
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Carberp.nxnte
BitDefenderThetaGen:NN.ZexaF.34058.Iq0@a0muvOck
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.hc
FireEyeGeneric.mg.b30494e5742b8e9d
EmsisoftGen:Variant.Ransom.Shade.27 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Carberp.nxnte
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Yakes
MicrosoftRansom:Win32/LockBit!ml
ArcabitTrojan.Ransom.Shade.27
ZoneAlarmTrojan.Win32.Yakes.vpjc
GDataGen:Variant.Ransom.Shade.27
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
McAfeeArtemis!B30494E5742B
VBA32BScope.TrojanSpy.Ursnif
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
YandexTrojan.Yakes!zx3ty/FViIg
IkarusTrojan.Win32.Crypt
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GAEW?

Win32/Kryptik.GAEW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment